GPO Sprawl


i took position allowed container admins (ca) add/adjust/create gpos. out of control. company has 138 ca accounts, , 636 gpo's listed. it's task under control. question pretty broad. start? have plan of attack i'd love hear others see their point of view. 

deann

i took position allowed container admins (ca) add/adjust/create gpos. out of control. company has 138 ca accounts, , 636 gpo's listed. it's task under control. question pretty broad. start? have plan of attack i'd love hear others see their point of view. 

deann

if in situation, following

  • backup gpo in case...
  • check delegation (yes, difficult task !) , remove desired users (if applicable)

ref: how view or delete active directory delegated permissions (en-us)

http://social.technet.microsoft.com/wiki/contents/articles/6477.how-to-view-or-delete-active-directory-delegated-permissions-en-us.aspx

  • check group policy creator owners group - remove users (if applicable)
  • check domain admins group - remove users (if applicable)
  • restrict users gpmc
  • create domain level policy , link ous
  • unlink unwanted gpos on ous 1 one
  • instruct admins not create or link gpos without approval during gpo sanitizing phase
  • before access permission revocation, make note of permissions set on containers, ids etc.. screen shots come in handy well

hth


i not represent organisation work for, opinions expressed here own.

this posting provided "as is" no warranties or guarantees , confers no rights.

- .... .- -. -.- ... --..-- ... .- -. - --- ... ....



Windows Server  >  Group Policy



Comments

Popular posts from this blog

directory stack

After enabling Windows Server 2012 R2 DHCP Failover Getting Packet dropped because of Client ID hash mismatch

WMI Repository 4GB limit - Win 2003 Ent Question